sevyn.

Sevyn — Data Processing Agreement (DPA)

Last updated: June 17, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Sevyn Software LLC ("Sevyn," "Processor," "Service Provider") and the customer that accepts it ("Customer," "Controller," "Business") for use of the Sevyn Service (the "Agreement"). It governs Sevyn's processing of personal information that Customer submits to the Service about Customer's own clients, end users, and personnel ("Customer Personal Data"). If there is a conflict between this DPA and the Agreement regarding personal data, this DPA controls.

Capitalized terms not defined here have the meaning in the Agreement. "Applicable Privacy Law" means U.S. state privacy laws that apply to the processing, including the California Consumer Privacy Act as amended ("CCPA") and the comprehensive privacy laws of Virginia, Colorado, Connecticut, and other states, as applicable.

1. Roles of the parties

Customer is the controller/business that determines the purposes and means of processing Customer Personal Data. Sevyn is the processor/service provider that processes Customer Personal Data only on Customer's documented instructions to provide the Service. The Agreement, this DPA, and Customer's configuration and use of the Service are Customer's complete and final instructions; additional instructions must be agreed in writing.

2. Scope of processing (required details)

  • Subject matter: provision of the Sevyn Service.
  • Duration: the term of the Agreement, plus the deletion/return period in Section 9.
  • Nature and purpose: hosting, storing, organizing, transmitting, displaying, and otherwise processing Customer Personal Data to provide estimating, proposals, job tracking, pricebook, budgeting, invoicing, client-portal, payment-facilitation, and AI-assisted features, and to secure and support the Service.
  • Types of personal data: identifiers and contact details (e.g., names, addresses, email, phone), project and property information, financial information (estimates, invoices, payment status), photos and documents that may depict people or property, and account/personnel data.
  • Categories of data subjects: Customer's clients (including homeowners), subcontractors, and Customer's own personnel/users.
  • Connected financial-account data (optional bank-sync): where Customer connects its own bank or card account (via Plaid), the transactions and account metadata Sevyn processes to categorize Customer's job costs. This is Customer's own business data, for which Sevyn acts as a controller under the Privacy Policy rather than as a processor of data about Customer's clients. To the extent any such data identifies third parties (for example, transaction counterparties), Sevyn processes it consistent with this DPA.

3. Sevyn's obligations as processor / service provider

Sevyn will:

  1. Process only on instructions. Process Customer Personal Data only for the purpose of providing the Service and only on Customer's documented instructions, and not for any other purpose.
  2. No sale; no sharing; no retention/use/disclosure outside the relationship. Not sell or share Customer Personal Data, and not retain, use, or disclose it (a) for any purpose other than providing the Service, including not for any "commercial purpose" other than the services, or (b) outside the direct business relationship between the parties, except as permitted by Applicable Privacy Law. Sevyn certifies that it understands and will comply with these restrictions.
  3. No combining. Not combine Customer Personal Data with personal information from other sources, except as permitted by Applicable Privacy Law to provide the Service.
  4. Confidentiality. Ensure personnel authorized to process Customer Personal Data are bound by confidentiality obligations.
  5. Security. Implement and maintain reasonable technical and organizational measures designed to protect Customer Personal Data appropriate to the risk (see Section 6).
  6. Assist with data-subject requests. Provide reasonable assistance, through appropriate technical and organizational measures and Service functionality (such as export, correction, and deletion tools), to help Customer respond to data-subject requests and to honor consumer rights under Applicable Privacy Law.
  7. Assist with security, breach, and assessments. Provide reasonable assistance to Customer with security of processing, breach notification, and any data-protection assessments required by Applicable Privacy Law, taking into account the information available to Sevyn.
  8. Notify of non-compliance. Notify Customer if Sevyn determines it can no longer meet its obligations under Applicable Privacy Law, in which case Customer may take reasonable steps to stop and remediate unauthorized processing.
  9. Enable monitoring. Make available information reasonably necessary to demonstrate compliance and allow for, and contribute to, assessments as described in Section 7.

4. Customer's obligations as controller

Customer will: (a) comply with Applicable Privacy Law in its own role; (b) provide all required notices to, and obtain all required consents from, its data subjects (including homeowners) for Sevyn to process Customer Personal Data as described; (c) ensure it has the right to submit Customer Personal Data to the Service; and (d) give instructions that comply with law.

5. Subprocessors

5.1 Customer provides general authorization for Sevyn to engage subprocessors to provide the Service. Sevyn's current subprocessors are listed at our subprocessor list.

5.2 Sevyn will impose data-protection obligations on each subprocessor that are at least as protective as those in this DPA, and remains responsible to Customer for its subprocessors' performance.

5.3 Sevyn will maintain the subprocessor list and provide a mechanism to be notified of new subprocessors. Customer may object on reasonable data-protection grounds within 15 days of notice; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected Service.

6. Security measures

Sevyn maintains reasonable safeguards designed to protect Customer Personal Data, which currently include: access controls and authentication; encryption of data in transit and, where applicable, at rest; tenant isolation so that data is scoped to the Customer's account; logging and monitoring; least-privilege access for personnel; vendor due diligence; and an incident-response process. Sevyn may update these measures provided protection is not materially reduced.

7. Audits and assessments

On reasonable prior written request, no more than once per year (unless required more often by a regulator or following a security incident), Sevyn will make available information reasonably necessary to demonstrate compliance with this DPA, which may take the form of Sevyn's then-current security documentation, summaries, or third-party reports. If that is insufficient to meet a requirement of Applicable Privacy Law, the parties will arrange a reasonable assessment, subject to confidentiality and Sevyn's security and operational constraints.

8. Personal data breach

Sevyn will notify Customer without undue delay after becoming aware of a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data. The notice will include the information reasonably available to Sevyn to help Customer meet its own notification obligations. Sevyn will take reasonable steps to mitigate and remediate.

9. Return and deletion

On termination or expiration of the Agreement, and on Customer's request, Sevyn will delete or return Customer Personal Data. Sevyn will make Customer Personal Data available for export for 30 days after termination, after which it will delete Customer Personal Data in the ordinary course, except for copies in routine backups that expire on a rolling basis and information Sevyn must retain to comply with law. Deletion obligations do not require deletion from immutable backups before their scheduled expiry.

10. International transfers

The Service is operated in the United States and Customer Personal Data is processed in the United States. This DPA does not contemplate transfers subject to EU/UK data-transfer mechanisms; if that changes, the parties will agree appropriate terms.

11. Liability; term; miscellaneous

Each party's liability under this DPA is subject to the limitations of liability in the Agreement. This DPA takes effect when Customer accepts it (or accepts the Agreement) and continues for as long as Sevyn processes Customer Personal Data. If any provision is unenforceable, the rest remains in effect. The governing law and dispute-resolution terms of the Agreement apply to this DPA.


How to execute. This DPA is incorporated into and accepted with the Agreement; no signature is required. Customers who require a counter-signed copy may request one at legal@getsevyn.com.

Terms of ServicePrivacy PolicyAcceptable UseData ProcessingSubprocessors
© 2026 Sevyn Software LLC · Wayne, NJ